Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Caldera

MyDoom Windows Worm DDoSing SCO 694

We mentioned the myDoom Worm just a few hours ago, but more information is available now, mainly that its ultimate goal is apparently to DDoS SCO. You can see some more detail at NetCraft. Obviously SCO has a lot of enemies out there right now, but it's always sad to watch someone stoop to this level.
This discussion has been archived. No new comments can be posted.

MyDoom Windows Worm DDoSing SCO

Comments Filter:
  • by Anonymous Coward on Tuesday January 27, 2004 @09:42AM (#8098796)
    Quick, disable your AV software, and get some Windows boxes on the internet!
  • by Anonymous Coward on Tuesday January 27, 2004 @09:43AM (#8098807)
    Maybe theyll change their domain name like M$ did to bastards.sco.com instead of sco.com/bastards
  • by r0xah ( 625882 ) on Tuesday January 27, 2004 @09:44AM (#8098812)
    This may not be the most appropriate way to attack SCO, but after all the FUD they have released and the actions they have taken it puts a smile on my face to see something like this come about. I hope their server gets toasted. Bring on the worms!
  • by Bigman ( 12384 ) on Tuesday January 27, 2004 @09:45AM (#8098827) Homepage Journal
    Lol
    Seriously, its is a shame, it will only fuel Darl's paranoia.
  • by G4from128k ( 686170 ) on Tuesday January 27, 2004 @09:46AM (#8098840)
    Seems like this is Linux's ultimate weapon of mass destruction because:

    1. The virus makes M$ operating systems look bad.
    2. The DDoS attack goes after every Linux lover's most hated target, SCO.

    But I do feel sorry for the people forced to used Windows by PHBs or who are novice users that don't know better than to run e-mailed executables.
  • by swordboy ( 472941 ) on Tuesday January 27, 2004 @09:47AM (#8098842) Journal
    Better yet, go here [sco.com] and keep clicking refresh - maybe you'll be the first to see the DDoS taking place!
  • ed (Score:5, Funny)

    by ballpoint ( 192660 ) on Tuesday January 27, 2004 @09:47AM (#8098843)
    but it's always sad to watch someone stoop to this level

    s/is/eir

  • by orty78 ( 707288 ) on Tuesday January 27, 2004 @09:48AM (#8098859)
    This is very similar to the SETI@Home project. I'd like to try it out and run it for a while. How and where do I sign up?
  • by dkleinsc ( 563838 ) on Tuesday January 27, 2004 @09:48AM (#8098865) Homepage
    If you really wanted to DoS SCO, why not just use the Slashdot Effect, like this: litigous bastards [sco.com]
  • by account_deleted ( 4530225 ) on Tuesday January 27, 2004 @09:49AM (#8098873)
    Comment removed based on user account deletion
  • by Anonymous Coward on Tuesday January 27, 2004 @09:50AM (#8098874)
    I've not yet received the virus in my email

    What's your address? I can send it to you...
  • by Anonymous Coward on Tuesday January 27, 2004 @09:52AM (#8098888)
    Can someone email the virus please?
  • by CaptainAlbert ( 162776 ) on Tuesday January 27, 2004 @09:52AM (#8098890) Homepage


    Seems like it's about time SCO came up with a new business model. Here's my suggestion:

    FROM: Mr. Darl McBride
    Santa Cruz Organisation
    Lindon, Utah

    Dear Sir:

    I have been requested by the Santa Cruz Organisation to contact you for assistance in resolving a matter. The Santa Cruz Organisation has recently concluded a large number of dubious security trades. These pump-and-dump operations have immediately produced moneys equalling US$75,000,000. The Santa Cruz Organisation is desirous of setting up business in other parts of the world, however, because of certain regulations of the U.S. Government, it is unable to move these funds to another region.

    Your assistance is requested as a non-U.S. citizen to assist the Santa Cruz Organisation in moving these funds out of the U.S. If the funds can be transferred to your name, in your Swedish account, then you can forward the funds as directed by the Santa Cruz Organisation. In exchange for your accomodating services, the Santa Cruz Organisation would agree to allow you to retain 10%, or US$7.5 million of this amount.

    However, to be a legitimate transferee of these moneys according to U.S. law, you must hold at least one license for Santa Cruz Organisation Intellectual Property, which are available at a cost of US$699.

    If it will be possible for you to assist us, we would be most grateful. We suggest that you meet with us in person in Lindon, and that during your visit I introduce you to the representatives of the Santa Cruz Organisation.

    Please call me at your earliest convenience. Time is of the essence in this matter; very quickly the U.S. Government will realize that the Federal Reserve is maintaining this amount on deposit, and attempt to levy certain depository taxes on it.

    Yours truly, etc.

    Darl McBride

  • YESSSSSSS. (Score:0, Funny)

    by -Maurice66- ( 728513 ) on Tuesday January 27, 2004 @09:52AM (#8098892)
    Where can I download the virus?

    I'll do everything to bug sco.

    M
  • by jimicus ( 737525 ) on Tuesday January 27, 2004 @09:53AM (#8098900)
    Anyone whose computer is infected with this worm is violating our IP! You must pay $699 for a license!
  • by mirko ( 198274 ) on Tuesday January 27, 2004 @09:54AM (#8098911) Journal
    A young boy walks into a whorehouse dragging a crushed frog on a string. He goes up to the madam and says, "
    I'd like to have the service of one of your young ladies, but she's gotta have herpes."

    The madam, taken aback by the boy, asks him, "Little boy, why on earth would you want to ruin your life at such an early age?"

    The boy says, "I don't want to explain, Either you help me out or I'll go somewhere that will!"

    The madam figures his money is better spent here than somewhere else, and takes him into the back to meet his lady.

    About an hour later the boy, still dragging the frog, tries to pay for his time.

    "Keep your money", said the Madam, "but I've just got to know why a boy your age wants herpes so badly. Won't you please tell me?"

    The boy takes a deep breath and sighs. "Ma'am, you see this frog? When I go home tonight, mom and dad are going out, and the babysitter will come over. And the babysitter will get the herpes. Then mom and dad will come home, dad will take the babysitter home, and dad will get herpes. When mom and dad go to bed tonight, mom will get herpes. Tomorrow, I'll go to school, dad will go to work, and the milkman will get herpes.
    And the milkman,
    " the boy sobbed, "the milkman is the son of a bitch who ran over my frog!"


    Now, with a proper sed'ing :
    A young skr1pt k1dd13z walks into a whorehouse dragging a crushed computer on a string. He goes up to the spammer and says, "
    I'd like to have the service of one of your young bulkers, but she's gotta have MyDoom."

    The spammer, taken aback by the skr1pt k1dd13z, asks him, "Little skr1pt k1dd13z, why on earth would you want to ruin your life at such an early age?"

    The skr1pt k1dd13z says, "I don't want to explain, Either you help me out or I'll go somewhere that will!"

    The spammer figures his money is better spent here than somewhere else, and takes him into the back to meet his bulker.

    About an hour later the skr1pt k1dd13z, still dragging the computer, tries to pay for his time.

    "Keep your money", said the spammer, "but I've just got to know why a skr1pt k1dd13z your age wants MyDoom so badly. Won't you please tell me?"

    The skr1pt k1dd13z takes a deep breath and sighs. "Spammer, you see this computer? When I go home tonight, proxy server and exchange server are going out, and the mail gateway will come over. And the mail gateway will get the MyDoom. Then proxy server and exchange server will come home, exchange server will take the mail gateway home, and exchange server will get MyDoom. When proxy server and exchange server go to bed tonight, proxy server will get MyDoom. Tomorrow, I'll go to school, exchange server will go to work, and Darl will get MyDoom.
    And Darl,
    " the skr1pt k1dd13z sobbed, "Darl is the son of a bitch who ran over my computer!"
  • by Anonymous Coward on Tuesday January 27, 2004 @09:55AM (#8098917)
    > I thought the worm was set to start the DDOS on February 1. So why is SCO
    > showing a DDOS right now?

    I guess some people have been playing with their system clocks to get around lame trial-period software?
  • by Anonymous Coward on Tuesday January 27, 2004 @09:56AM (#8098930)
    Is the source available on GPL?

    No, but you can buy the SDK here [amazon.co.uk].
  • by Anonymous Coward on Tuesday January 27, 2004 @09:57AM (#8098937)
    Here's the great thing about it, you don't have to, you get invited!
  • by julesh ( 229690 ) on Tuesday January 27, 2004 @09:58AM (#8098949)
    Assuming you're talking about the Windows Update DDOS, you probably mean bastards.com.
  • by ArseneLupin ( 743401 ) on Tuesday January 27, 2004 @09:59AM (#8098959)
    Seems like this is Linux's ultimate weapon of mass destruction because:

    Didn't you get it? There are no weapons of mass destruction! It was all made up by Darl and his cronies!

  • by julesh ( 229690 ) on Tuesday January 27, 2004 @10:01AM (#8098969)
    You're in luck. Just run your standard Windows e-mail client, publish your e-mail address on a web page, and start running all those nice screen savers people will e-mail to you. No sign up required.
  • by Pollux ( 102520 ) <speter AT tedata DOT net DOT eg> on Tuesday January 27, 2004 @10:01AM (#8098974) Journal
    Obviously SCO has a lot of enemies out there right now, but it's always sad to watch someone stoop to this level.

    Quick, disable your AV software, and get some Windows boxes on the internet!

    You know, this reminds me of one time when an apartment building in our neighborhood was burning. Sure, you felt sorry to see it burn, and you felt sorry to see the people who lived there get hurt, but man, it's really fun to watch a building burn!

    Really, there was one guy in the group who came out in a lawn chair with a six pack and watched it all happen. Raised his beer with a "Hell yea!" when the wooden frame structure collapsed.
  • by PhilHibbs ( 4537 ) <snarks@gmail.com> on Tuesday January 27, 2004 @10:03AM (#8098987) Journal
    00:00 blinking on their VCRs
    There's agreat new solution solution [homestarrunner.com] to that problem.
  • by chendo ( 678767 ) on Tuesday January 27, 2004 @10:03AM (#8098988)
    In fact, you can sign up for SCO's Expulsion and Termination Intiative at Home program simply by clicking here [sco.com]. Remember, the more times you click it, the higher your score will be!

    I hope someone comes up with a better acronym ;p
  • by rogabean ( 741411 ) on Tuesday January 27, 2004 @10:05AM (#8099006)
    I guess its time for me to get that windows machine back up and running...

    hmm on second thought, thousands of windows computers at work and just as many ignorant email users...

    As the article said, I hate to see anyone stoop this low, but SCO had it coming. You can anger windows users, because they don't know any better, but Linux users? Well we fight back!
  • by TobascoKid ( 82629 ) on Tuesday January 27, 2004 @10:08AM (#8099025) Homepage
    Well maybe they didn't write it, but Im sure there is some SCO code in it.

    While some may consider that the virus is "derived" from SCO intellectual property, it doesn't contain actual SCO code.
  • So sad (Score:5, Funny)

    by Pedrito ( 94783 ) on Tuesday January 27, 2004 @10:15AM (#8099094)
    Obviously SCO has a lot of enemies out there right now, but it's always sad to watch someone stoop to this level.

    Yes, it makes me very sad. Can someone hand me a hanky? I think I need some alone time to cry about this.
  • by swordboy ( 472941 ) on Tuesday January 27, 2004 @10:15AM (#8099098) Journal
    The funny thing is that the virus isn't even supposed to start the DDoS until February 1st... STOP CLICKING HERE PEOPLE! [sco.com]
  • by Anonymous Coward on Tuesday January 27, 2004 @10:16AM (#8099102)
    SCO@Home: Help Darl Find That Copyrighted Code.
  • by loucura! ( 247834 ) on Tuesday January 27, 2004 @10:19AM (#8099129)
    Sorry, that was me. I was trying to find out who wins the Superbowl and what the spread was so I can go bet at my bookie.

    --Joe Sixpack.
  • Pirates? (Score:5, Funny)

    by Aldric ( 642394 ) on Tuesday January 27, 2004 @10:20AM (#8099140)
    I never even knew that SCO owned any ships, never mind that one of them had been boarded and plundered by pirates.
  • by TedCheshireAcad ( 311748 ) <ted AT fc DOT rit DOT edu> on Tuesday January 27, 2004 @10:20AM (#8099141) Homepage
    This attack only helps SCO. They get sympathy. What do the worm writers get?

    Sir, it is obvious you have little to no understanding of the 1337 script kiddie culture. In exchange for a DDOS attack, the worm writers get something called mad pr0pz, which is a form of honor and integrity among those in the community.
  • by x-router ( 694339 ) <richard@x-r[ ]er.com ['out' in gap]> on Tuesday January 27, 2004 @10:22AM (#8099158)
    Better yet can someone send me the virus in a handy network install so I can role it out onto our corp nets?
  • by o'reor ( 581921 ) on Tuesday January 27, 2004 @10:23AM (#8099178) Journal
    After a few clicks I got this :

    Server Error

    The following error occurred:
    [code=SERVER_RESPONSE_RESET] The server response could not be read because of an error. Contact your system administrator.

    Please contact the administrator.

    Woo-hoo ! I DoSed the SCO server with only one finger !

  • by kinnell ( 607819 ) on Tuesday January 27, 2004 @10:25AM (#8099206)
    I thought the worm was set to start the DDOS on February 1. So why is SCO showing a DDOS right now?

    Due to the speed of the modern information infrastructure, and the method by which this virus distributes itself, a considerable number of copies will have crossed the international dateline several times during transmission. For these, it is indeed February 1st, and therefore these viruses are functioing correctly. Of course a similar number will have crossed in the other direction, so we can expect to see new DDOS attacks on SCO at least until February 5th

  • by stubblehead ( 565808 ) on Tuesday January 27, 2004 @10:25AM (#8099210)
    Well, at least SOME type of Doom has been released... (even if it's not D3)
  • by D-Cypell ( 446534 ) on Tuesday January 27, 2004 @10:27AM (#8099229)
    apparently they switched from SCO UNIX to Linux in August 2002...

    Remember, SCO cant see the distinction!
  • by whitelabrat ( 469237 ) on Tuesday January 27, 2004 @10:31AM (#8099263)
    Is there anywhere I can go to get this virus?
  • by Anonymous Coward on Tuesday January 27, 2004 @10:36AM (#8099314)
    Dear Sir or Madam,

    your Internet Protocol number has been logged for legal purposes in accordance with our efforts to reduce the increasing amount of abusive usage of this site's functionality and to comply with the Rules Of Governance In Electronic Media as required by Californian law.

    We are to inform you of the legal steps taken against the holder of mentioned number, which we hereby do.

    Please refer to the Bureau Of The Attorney Of Los Angeles (CA) county [la.ca.us] to request your case number, as this message is generated electronically and we have no means to determine the case number at this moment.

    Thank you.
  • by Anonymous Coward on Tuesday January 27, 2004 @10:47AM (#8099439)
    What the hell, lets slashdot them too.
  • by Thor Ablestar ( 321949 ) on Tuesday January 27, 2004 @10:49AM (#8099453)
    where real human beings take their opressors to court, and pirates initiate violent action against those they dislike.


    Thief (targeting a pistol): Money, quickly!

    Real Human Being (With a disarming smile): Mr Thief, Would you like to visit a court with me in order to resolve our conflict? I just happen to have some megabucks to spend for our litigation!

  • by clarkc3 ( 574410 ) on Tuesday January 27, 2004 @10:51AM (#8099479)
    On the bottom of the netcraft report you can see an OS history of www.sco.com - apparently they switched from SCO UNIX to Linux in August 2002...

    I'm sure they just gave themselves a license and wrote off the $699 on their taxes as a business expense ;)

  • by peter_gzowski ( 465076 ) on Tuesday January 27, 2004 @10:53AM (#8099492) Homepage
    But they need someone to DDoS IBM before they can figure out what code...
  • by zhenlin ( 722930 ) on Tuesday January 27, 2004 @10:56AM (#8099524)
    Santa Cruz Operation is now known as Tarantella, and is not the SCO Group, that is resposible for The FiaSCO.
  • by Trygve ( 75999 ) on Tuesday January 27, 2004 @11:02AM (#8099586)
    such acts of terrorism

    <sarcasm>
    Quick, call the Patriot Act Police [bushin30seconds.org], some linux using terrorists wrote some code to ping that good God loving American company, The SCO Group! Abusing them with their own IP, the gall of it!! </sarcasm>

  • by LilMikey ( 615759 ) on Tuesday January 27, 2004 @11:15AM (#8099744) Homepage
    Woo-hoo ! I DoSed the SCO server with only one finger !

    Guess what SCO's doing with their finger.
  • by unoengborg ( 209251 ) on Tuesday January 27, 2004 @11:16AM (#8099765) Homepage
    Doing DDoS on SCO just makes people feel sorry for them. They do not deserve that.

    Besides SCO doesn't need the internet as they hardly can expect to have any real customers left.

    Nowdays their business model is based purely on litegation. To my knowledge lawsuits are delivered by hand, so a DDoS would not disturb their business at all.

  • by scoove ( 71173 ) on Tuesday January 27, 2004 @11:19AM (#8099804)
    [Darl] You see the stock yesterday? Kept going down. And hard. I even heard the analysts are onto our scam.

    [Bob] Yup. It's getting just plain impossible to dump this stock [macobserver.com] anymore. What do we do? We got hammered on that 'dog ate our homework' line on our court filing last week. What do you think David? You guys did a bang up job making it look like Gore won Florida when there was no way a recount would ever show that. Hell, half the country still believes that 'selected, not elected' crap.

    [Boies] Well I always say, play offense, not defense. We need to get the public back on our side. Control the spin. You know, make us out to be the victim again. It plays into these schmucks capability for pity.

    [Darl] I got it! What if we were being attacked by evil hackers again? (laughs)

    [Boies] Bingo. What can your geeks whip up quick, Darl?

    [Darl] Well they sure ain't coding operating systems and their time spent looking for code violations in Linux has been a big waste. Maybe we could put them on making some sort of johnson or trojan or something that attacks our Internet connection. Bench, you think that'd help our numbers?

    [Bob] Might. What'da say Dave?

    [Boies] Hell, it'd be perfect! I'd bet it'd not only turn the PR our way, but I could put that half-assed son of Hatch's to business suing Internet service providers for causing our business damage. And if we totally bomb in court with this asshole judge, we'll just claim the whole company imploded cause of the Internet hacks and sue the pants off of every provider.

    [Darl] Love it! Hey, let's call it some prophetic name like SCO doom or our doom like those bozos at the church are always yacking about end of world crap. Should get them riled up too. And hey, it might just be true for SCO! To the bank, buddies!

  • by morelife ( 213920 ) <f00fbug&postREMOVETHISman,at> on Tuesday January 27, 2004 @11:20AM (#8099807)
    DDOSing SCO's web site only prevents the general public and groklaw.net from access to their ongoing press releases and Darl's bio -- I mean -- does www.sco.com get traffic for any /other/ reason? People checking for Openserver upgrades and enhancements?? The latest download of Skunkware?? A fresh copy of the $699. Linux Licensing form???
  • by Thor Ablestar ( 321949 ) on Tuesday January 27, 2004 @11:40AM (#8100011)
    I hate the techno terrorists, but...

    SCO will be broken by the weight of justice and right, not by mindless thugware.

    Some time ago I had a hope that Microsoft will be broken by the weight of justice and right plus weight of users' dissatisfaction...
  • by Anonymous Coward on Tuesday January 27, 2004 @11:44AM (#8100052)
    Troll McBride: muahhaha! now time for another press release!

    Agent MyDoom: but how will your make a press release... if you are unable to speak?

    Troll McBride: you can't stop me I am the one!

    Agent MyDoom: well there's me

    Agent MyDoom2: and me

    Agent MyDoom3: and me

    Agent MyDoom4: and me

    Agent MyDoom5: and me

    Agent MyDoom6: and me

    *fight ensues*
    But you can't keep a good troll down, and MyDoom is defeated by Troll McBride's pure force of will.

    --cut to the alternate world where charaters now have different roles --

    Troll McBride: source code? there is no source code.

    Novell: it's not in your OS my love.

    Troll McBride: but it's just a game

    Novell: so is this, have fun.

    Troll McBride: alright, alright, let us see where this goes. You two, get the source code.

    *two main lawyers go all sinister and transparent and sink into the ground*

    Linus: that's a nice trick.

    Tux: I cannot go back! *slides away ala tux racer*

    IBM: I'll handle them. *linus and perens run after tux*

    Troll McBride: handle us? you'll handle us? you know your unix heritage had much more respect. *signals to other lawyers*

    *lawyers release a barrage of photocopied source code, and discovery requests at IBM*

    *IBM holds up judges orders for real evidence, shit flying through air is halted and falls to the ground*

    Troll McBride: o..k.., you have some skill - FUD him.

    *the PR men hiding in laywers suits begin to duck and weave their PR attacks*

    NEXT EPISODES OF ABSURD-I-SCO-TRICKS HAVE YET TO BE FINALIZED... KEEP WATCHING.

  • by CrankyFool ( 680025 ) on Tuesday January 27, 2004 @11:55AM (#8100180)
    There is no patch and there can be no technical patch. This thing propagates by social engineering -- the 'click here' vulnerability. It's not the RPC/DCOM worm. You'll need to patch people.

  • by RetroGeek ( 206522 ) on Tuesday January 27, 2004 @12:18PM (#8100472) Homepage
    yea except that it infects windows machines :) not linux

    So then they run through all possible IP addresses and throw out the ones doing a DoS (ie: Windows).

    The rest are obviously in violation.
  • RIAA (Score:2, Funny)

    by SpyPlane ( 733043 ) on Tuesday January 27, 2004 @12:23PM (#8100542)
    The RIAA did it.

    1) Attacks users of Kazaa
    2) Attacks evil corporation on top and finally returns RIAA to their hard fought spot!

  • by falzer ( 224563 ) on Tuesday January 27, 2004 @12:24PM (#8100558)
    Hey, that's my birthday!

    Aw geez, you guys shouldn't have!
  • by gotem ( 678274 ) on Tuesday January 27, 2004 @01:06PM (#8101107) Homepage Journal
    maybe you can find extraterrestrial intelligence, but looking for intelligence at SCO? that doesn't seem likely
  • by dspfreak ( 666482 ) on Tuesday January 27, 2004 @01:48PM (#8101648)
    But that's the price you have to pay if you want to get nekkid with one of those hot chicks in those flowery little dresses that ride around on bikes and tire swings and stuff in the commercials. Mmmm... herpes.
  • by Ironica ( 124657 ) <pixel@bo o n d o c k.org> on Tuesday January 27, 2004 @03:08PM (#8102711) Journal
    That is like, the silliest thing I have ever heard. If you are not trolling, then I pity your utter lack of thought on the matter.

    The international date line isn't some magical gateway that adds or subtracts from your date. It doesn't work like that.


    /. really needs a "-1, didn't get the joke" mod... ;-)
  • by lildogie ( 54998 ) on Tuesday January 27, 2004 @03:53PM (#8103256)
    Well, there must be some Linux code in it. I can't say what code, but my engineers are doing a source scan right now.

    Since there is Linux code in the virus, even a small amount of Linux code, then the virus must belong to SCO, because SCO owns Linux.

    Since SCO owns the virus, they're guilty, and they owe a lot of people a whole lot of money.
  • by Darth23 ( 720385 ) on Tuesday January 27, 2004 @06:28PM (#8105227) Journal
    I just read abot the SCO connection on CNN (busy day today). Interesting symbolism, using Microsoft Windows vulnerabilities to attack a company that's trying to 'close-source' Linux.

The key elements in human thinking are not numbers but labels of fuzzy sets. -- L. Zadeh

Working...